US2011066851A1PendingUtilityA1

Secure Route Discovery Node and Policing Mechanism

Assignee: IBMPriority: Sep 14, 2009Filed: Sep 14, 2009Published: Mar 17, 2011
Est. expirySep 14, 2029(~3.1 yrs left)· nominal 20-yr term from priority
H04L 45/42H04L 63/105H04L 63/04H04L 63/08
55
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

A computer implemented method and computer program product for obtaining a secure route. A trusted host sets a node security association for a trusted host. The trusted host receives, at the trusted host, a client communication request directed to a destination host. The trusted host builds a secure route query comprising a trusted host address, a destination host address, and at least one security level, to form at least one secure route. The trusted host sends packets from the trusted host to the destination host based on the at least one secure route. The packets are responsive to the client communication request, and the packets each have a security label that matches the security level.

Claims

exact text as granted — not AI-modified
1 . A computer implemented method for identifying a source router, the computer implemented method comprising:
 transmitting a multicast packet, wherein the multicast packets defines a security level and neighbor secure router for a secure router;   receiving at least one packet above the security level associated with the secure router; and   responsive to receiving the at least one packet having a classification level above the security level, transmitting a source address of the at least one packet to a secure route discovery node.   
     
     
         2 . The computer implemented method of  claim 1 , further comprising:
 setting an address of the secure route discovery node; and   wherein transmitting the source address comprises transmitting the source address to the address of the secure route discovery node.   
     
     
         3 . The computer implemented method of  claim 1 , wherein the at least one packet conforms to multilevel security standard. 
     
     
         4 . The computer implemented method of  claim 1 , further comprising:
 responsive to receiving the at least one packet having a classification level above the security level, dropping the at least one packet.   
     
     
         5 . The computer implemented method of  claim 1 , further comprising:
 receiving at least one packet at or below the clearance level associated with the secure router; and   transmitting the at least one packet at or above the clearance level.   
     
     
         6 . The computer implemented method of  claim 5 , wherein transmitting the at least one packet is by using a strict source route internet protocol. 
     
     
         7 . A computer implemented method for obtaining a secure route, the computer implemented method comprising:
 setting a node security association for a trusted host;   receiving, at the trusted host, a client communication request directed to a destination host;   building a secure route query comprising a trusted host address, a destination host address, and at least one security level, to form at least one secure route; and   sending packets from the trusted host to the destination host based on the at least one secure route, wherein the packets are responsive to the client communication request, and the packets each have a security label that matches the security level.   
     
     
         8 . The computer implemented method of  claim 7 , wherein sending packets further comprises:
 setting a strict source route option on each packet.   
     
     
         9 . The computer implemented method of  claim 7 , wherein building further comprises:
 determining whether the destination host is described in a secure route cache at the trusted host; and   responsive to a determination that the destination host is in the secure route cache, forming the secure route based on the secure route cache.   
     
     
         10 . The computer implemented method of  claim 7 , wherein building further comprises:
 determining whether the destination host is described in a secure route cache;   responsive to a determination that the destination host is not in the secure route cache, transmitting the secure route query to a secure route discovery host;   receiving a secure route discovery node response;   determining whether the secure route discovery node response is non-empty; and   responsive to a determination that the secure route discovery node response is non-empty, storing at least one secure route of the secure route discovery node response to the secure route cache based on the secure route discovery node response.   
     
     
         11 . The computer implemented method of  claim 10 , further comprises:
 setting a cache time for the at least one secure route.   
     
     
         12 . The computer implemented method of  claim 11 , further comprising:
 determining a cache time expiration with respect to at least one secure route; and   responsive to a determination that the cache time has expired, deleting the at least one secure route from the secure route cache.   
     
     
         13 . The computer implemented method of  claim 10 , further comprising:
 responsive to receiving a secure route discovery node response, caching the at least one secure route in the secure route cache response for a tunable cache time.   
     
     
         14 . A computer implemented method to direct at least one secure router, the method comprising:
 receiving a secure route query from a trusted host, the secure route query comprising a trusted host address, a destination host address and a one classification level;   looking up at least one path having as endpoints, a trusted host and a destination host; and   responsive to finding a path, transmitting a secure route discovery node response.   
     
     
         15 . The computer implemented method of  claim 14 , wherein looking up at least one path further comprises:
 finding a network segment having one endpoint selected from the group consisting of trusted host and destination host, the network segment having a clearance level at least as high as the one classification level such that the network segment and at least one additional network segments interconnect trusted host and destination host, wherein the each additional network segment has endpoints each having a clearance level at least as high as the one classification level.   
     
     
         16 . The computer implemented method of  claim 14 , wherein looking up the at least one path further comprises:
 locating only one or more inadequate paths to interconnect trusted host and destination host via secure routers having clearance levels at or above the classification level; and   responsive to locating only one or more inadequate paths, transmitting the secure route discovery node response as a packet to the trusted host, the packet having an empty string.   
     
     
         17 . The computer implemented method of  claim 14 , further comprising:
 receiving a multicast packet having a secure router and a clearance level associated with the secure router; and   building a secure routes database having at least one network segment having the secure router as an endpoint, wherein the at least one network segment is associated with a clearance level at or below the clearance level associated with the secure route discovery node, wherein the looking up is with reference to the secure routes database.   
     
     
         18 . A computer program product for obtaining a secure route, the computer program product comprising: a computer usable medium having computer usable program code embodied therewith, the computer program product comprising:
 computer usable program code configured to set a node security association for a trusted host;   computer usable program code configured to receive, at the trusted host, a client communication request directed to a destination host;   computer usable program code configured to build a secure route query comprising a trusted host address, a destination host address, and at least one security level, to form at least one secure route; and   computer usable program code configured to send packets from the trusted host to the destination host based on the at least one secure route, wherein the packets are responsive to the client communication request, and the packets each have a security label that matches the security level.   
     
     
         19 . The computer program product of  claim 18 , wherein sending packets further comprises:
 computer usable program code configured to set a strict source route option on each packet.   
     
     
         20 . The computer program product of  claim 18 , wherein building further comprises:
 computer usable program code configured to determine whether the destination host is described in a secure route cache at the trusted host; and   computer usable program code configured to form the secure route based on the secure route cache, responsive to a determination that the destination host is in the secure route cache.   
     
     
         21 . The computer program product of  claim 18 , wherein building further comprises:
 computer usable program code configured to determine whether the destination host is described in a secure route cache;   computer usable program code configured to transmit the secure route query to a secure route discovery host responsive to a determination that the destination host is not in the secure route;   computer usable program code configured to receive a secure route discovery node response;   computer usable program code configured to determine whether the secure route discovery node response is non-empty; and   computer usable program code configured to store at least one secure route of the secure route discovery node response to the secure route cache based on the secure route discovery node response, responsive to a determination that the secure route discovery node response is non-empty.   
     
     
         22 . The computer program product of  claim 21 , further comprising:
 computer usable program code configured to set a cache time for the at least one secure route.   
     
     
         23 . The computer program product of  claim 22 , further comprising:
 computer usable program code configured to determine a cache time expiration with respect to at least one secure route; and   computer usable program code configured to delete the at least one secure route from the secure route cache, responsive to a determination that the cache time has expired.   
     
     
         24 . The computer program product of  claim 21 , further comprising:
 computer usable program code configured to cache the at least one secure route in the secure route cache response for a tunable cache time, responsive to receiving a secure route discovery node response.

Join the waitlist — get patent alerts

Track US2011066851A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.